CVE-2018-6558
published 2018-08-23CVE-2018-6558: The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
0.62%
45.7th percentile
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fscrypt | < fscrypt 0.2.4-1 (bookworm) | fscrypt 0.2.4-1 (bookworm) |
| github.com | google_fscrypt | >= 0 < 0.2.4 | 0.2.4 |
| fscrypt | < 0.2.4 | 0.2.4 | |
| fscrypt | >= 0 < 0.2.4-1 | 0.2.4-1 | |
| fscrypt | >= 0 < 0.2.4-1 | 0.2.4-1 | |
| fscrypt | >= 0 < 0.2.4-1 | 0.2.4-1 | |
| fscrypt | >= 0 < 0.2.4-1 | 0.2.4-1 | |
| the_fscrypt_project | fscrypt | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:N/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-6558: fscrypt - The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary a...
vendor_debian·2018·CVSS 6.5
CVE-2018-6558 [MEDIUM] CVE-2018-6558: fscrypt - The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary a...
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
Scope: local
bookworm: resolved (fixed in 0.2.4-1)
bullseye: resolved (fixed in 0.2.4-1)
forky: resolved (fixed in 0.2.4-1)
sid: resolved (fixed in 0.2.4-1)
trixie: resolved (fixed in 0.2.4-1)
OSV
Privilege Escalation in fscrypt
osv·2021-06-23
CVE-2018-6558 [MEDIUM] Privilege Escalation in fscrypt
Privilege Escalation in fscrypt
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
GHSA
Privilege Escalation in fscrypt
ghsa·2021-06-23
CVE-2018-6558 [MEDIUM] Privilege Escalation in fscrypt
Privilege Escalation in fscrypt
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
OSV
Privilege escalation in github.com/google/fscrypt
osv·2021-04-14
CVE-2018-6558 Privilege escalation in github.com/google/fscrypt
Privilege escalation in github.com/google/fscrypt
After dropping and then elevating process privileges euid, guid, and groups are not properly restored to their original values, allowing an unprivileged user to gain membership in the root group.
OSV
CVE-2018-6558: The pam_fscrypt module in fscrypt before 0
osv·2018-08-23·CVSS 6.5
CVE-2018-6558 [MEDIUM] CVE-2018-6558: The pam_fscrypt module in fscrypt before 0
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/google/fscrypt/commit/3022c1603d968c22f147b4a2c49c4637dd1be91bhttps://github.com/google/fscrypt/commit/315f9b042237200174a1fb99427f74027e191d66https://github.com/google/fscrypt/issues/77https://launchpad.net/bugs/1787548https://github.com/google/fscrypt/commit/3022c1603d968c22f147b4a2c49c4637dd1be91bhttps://github.com/google/fscrypt/commit/315f9b042237200174a1fb99427f74027e191d66https://github.com/google/fscrypt/issues/77https://launchpad.net/bugs/1787548
2018-08-23
Published